CVE-2024-47358: WordPress Popup Maker plugin <= 1.19.2 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.
Affected Software
1 affected component
Code-atlantic Popup Maker Wordpress<1.20.0
Remediation
Information
Update to 1.20.0 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47358?
CVE-2024-47358 has a medium severity rating due to the missing authorization that can lead to unauthorized access.
2
How do I fix CVE-2024-47358?
To fix CVE-2024-47358, update Popup Maker to version 1.20.0 or later to ensure proper access controls are implemented.
3
What is the impact of CVE-2024-47358?
The impact of CVE-2024-47358 allows attackers to gain access to functionalities that are not properly constrained by access control lists.
4
Which versions of Popup Maker are affected by CVE-2024-47358?
Popup Maker versions from n/a through 1.19.2 are affected by CVE-2024-47358.
5
Is there a workaround for CVE-2024-47358?
A temporary workaround for CVE-2024-47358 is to manually review and restrict access to vulnerable functionalities until an update is applied.